OpenSSF Charts Course Through CRA Compliance Wave, Debuts Kubernetes SBOM Tool
The Open Source Security Foundation is mobilizing its community around European regulatory deadlines while launching new projects and expanding its reach into agentic AI security.
Regulatory readiness dominates the August 2026 OpenSSF agenda, with a surge of resources aimed at helping organizations navigate the EU's Cyber Resilience Act ahead of critical reporting milestones. The foundation is simultaneously expanding its technical portfolio and convening experts across multiple conferences to address emerging security challenges in artificial intelligence systems.
Linux Reaches 35 Years; Kernel Security Remains Central to OpenSSF Mission
The Linux kernel marked its 35th anniversary this month, tracing its origins to Linus Torvalds' August 25, 1991 Usenet announcement describing it as "just a hobby, won't be big and professional." Today the kernel underpins servers, supercomputers, cloud platforms, and billions of mobile devices worldwide. OpenSSF explored the kernel's security trajectory in episode 64 of its What's in the SOSS? podcast, featuring Greg Kroah-Hartman, a longtime Linux kernel maintainer. The conversation covered how a weekend driver project evolved into 25+ years of maintenance work, the role of upstream bug fixes as a security strategy, and OpenSSF's collaboration with maintainers navigating global regulations including the CRA.
OpenSSF Sponsors AGNTCon + MCPCon, Advances Agentic AI Security
The foundation is serving as a Silver Sponsor at AGNTCon + MCPCon North America, scheduled for October 22–23, 2026 in San Jose, California. The event will feature OpenSSF community experts delivering workshops and talks on securing agentic AI systems, including hands-on sessions on the Secure Agentic Framework (SAF) and software supply chain defense strategies.
BOMHort Joins OpenSSF as Kubernetes-Native SBOM Platform
BOMHort, formerly known as SeeBOM, has been accepted into the OpenSSF Sandbox as a new project. Created by Mario Fahlandt, the platform provides Kubernetes-native software bill of materials visualization and governance capabilities designed to deliver centralized visibility and control over software supply chains at scale.
Ericsson Case Study Demonstrates CRA Compliance Through Upstream Collaboration
Ericsson Software Technology achieved CRA compliance by fundamentally restructuring its approach to open source engagement. The company eliminated private code forks and contributed more than 1,400 dependency updates and security fixes directly to upstream open source projects, guided by OpenSSF principles. This shift allowed the organization to meet the regulation's stringent obligations while strengthening the broader open source ecosystem.
CRA Compliance Guidance Released as September Deadline Approaches
OpenSSF published a practitioner-focused compliance guide as the September 2026 CRA reporting deadline draws near, with full compliance required by December 2027. The guidance addresses software manufacturers, commercial entities, open source stewards, and foundations, translating regulatory requirements into operational steps. The foundation also released a series of podcast episodes addressing CRA readiness from multiple angles.
OpenSSF Project Releases and Updates
Several OpenSSF projects released new versions this month. OpenBao v2.6 introduced per-namespace sealing and a cross-plugin workflow engine, drawing contributions from 42 first-time contributors, 27 individuals with multiple changes, and 8 users with double-digit contribution counts. OpenBao v2.6.2 followed with security fixes for inline authentication workflows and PKI IP SAN enforcement.
- Gemara v1.5.0 added evidence mapping support to Evidence and AssessmentPlan structures
- Minder v0.3.1 resolved server-side security vulnerabilities and exposed rule evaluation outputs to Starlark tests
- Zarf v0.83.0 added project vulnerability scanning with VEX statement support, improved pod security defaults, and schema validation options
- OSV Schema v1.9.0 introduced support for Homebrew and WordPress ecosystems plus wildcard package name support
- Sigstore released Cosign v3.1.3 and backported v2.6.5 to fix a verification bypass vulnerability in legacy bundles
- darnit announced its initial v0.1.0 release, providing security tooling integrations for MCP, PyPI, and container environments
Podcast Series Explores CRA Readiness and Open Source Funding
OpenSSF's What's in the SOSS? podcast released four new episodes addressing CRA compliance and open source sustainability. Episode 67 featured Mila Zhou, Open Source Program Manager at AWS, discussing the intersection of finance, strategy, and security in open source. Episode 68 covered practical CRA strategies with Megan Knight, who reviewed the compliance timeline and resources for maintainers. Episode 69 presented Roman Zhukov's "community garden" analogy for understanding CRA roles and exemptions. Episode 70 featured Dave Russo discussing the $250,000-per-release cost of maintaining private forks and Red Hat's "champion stewardship" framework.
Working Groups Advance CRA Implementation and Vulnerability Disclosure Standards
The Global Cyber Policy Working Group launched a CRA Podcast Series focused on practical readiness strategies and is gathering feedback on the new Cloud and AI Development Act for submission to the European Commission. The group also hosted a CRA Tech Talk featuring leaders from the Orbit Launchpad Special Interest Group, who presented progress on a machine-readable due diligence framework for open source software consumption, including tools such as the CRAB-FOSS catalog and Dell's Trustworthiness Calculator.
The Vulnerability Disclosures Working Group published the OSS Vulnerability Guide as a new website at oss-vulnerability-guide.openssf.org. The ORBIT Working Group announced that the Privateer sandbox application received Technical Advisory Committee approval and is beginning its formal donation process. The Secure Agentic Framework SIG is planning a hands-on workshop for agentic AI defenders at AGNTCon + MCPCon North America. The Best Practices Working Group is developing a Secure Coding Guide for Python, grounded in real-world CWEs and CVEs.
CRA Reporting Deadline and Regulatory Updates
The CRA's September 11, 2026 reporting deadline is imminent. On that date, manufacturers and open source stewards must report actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform. ENISA has updated its FAQs and published guidance documents including a two-page reporting factsheet, user registration instructions, and notification submission guidance.
The German Federal Office for Information Security (BSI) updated its TR-03183-1: Cyber Resilience Requirements document, clarifying CRA aspects and providing practical implementation guidance as part of its broader TR-03183 series. CISA, alongside international cybersecurity agencies, released the 2026 Minimum Elements for a Software Bill of Materials. ETSI launched an approval process for 17 EU CRA Vertical Standards. The European Parliament's Internal Market and Consumer Protection Committee submitted 593 amendments to the revised Cybersecurity Act and 91 amendments to the NIS2 directive revision.
Upcoming OpenSSF Events and Engagement Opportunities
- OpenSSF Community Day Europe 2026 – October 6, Prague, Czechia
- Open Source Summit Europe 2026 – October 7–9, Prague, Czechia
- All Things Open 2026 – October 19–20, Edinburgh, UK
- ETSI Security Conference 2026 – October 19–22, Sophia Antipolis, France
- AGNTCon + MCPCon North America – October 20–23, San Jose, CA
- Open Source SecurityCon North America 2026 – November 9, Salt Lake City, UT
- KubeCon + CloudNativeCon North America 2026 – November 9–12, Salt Lake City, UT
Individuals and organizations can participate in OpenSSF by joining a working group or project, connecting on Slack, following the foundation on X, Mastodon, Bluesky, and LinkedIn, or becoming a member. Feedback and suggestions for future newsletters can be sent to marketing@openssf.org.